Skip to content

Scope CI secret-scan history to what the run would land - #118

Merged
seathatflowsinourveins merged 1 commit into
mainfrom
claude/secret-scan-ancestry-scope-20260923
Sep 23, 2026
Merged

seathatflowsinourveins merged 1 commit into
mainfrom
claude/secret-scan-ancestry-scope-20260923

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Why

The secret-scan job runs gitleaks git . after actions/checkout with fetch-depth: 0. By default gitleaks scans every fetched ref, including every other open branch.

On 2026-09-23 this made PR #117's required check fail. Its secret-scan artifact secret-scan-35870341699 reported 4 generic-api-key findings. All four are in observability/memory-scheduled-20260923.json lines 132-144 at commit b801fe4, which is on PR #116's branch and is not an ancestor of #117. The flagged values are 64-hex rejection fingerprints under a "key" field. I inspected their length and charset only and did not print them; they look like false positives, but #116's owner has to review and fix them in #116.

Change

  • --log-opts="HEAD" in the git-mode scan. It now scans the ancestry of what the run would land: a PR's merge commit, or main on push. Each branch is still scanned in its own PR run. The working-tree dir scan is unchanged.
  • This resolves the scope decision that .gitleaks.toml (lines 101-108) and docs/github-automation.md had left to the coordinator. Both now record the resolution.

Alternative considered: keep all refs and require every open branch to be clean. Rejected, because it couples every PR's required check to unrelated branches. Overturn condition: a secret reaching main that an all-refs scan would have caught but an ancestry scan did not. That can't happen for commits that land, since they are ancestors of main.

Evidence

  • zizmor (offline, regular persona, strict collection): no findings.
  • validate.py: passed.
  • evidence_manifest.py --check: passed.
  • git diff --check: clean.
  • actionlint is not installed on this host; the validate job runs the pinned actionlint.
  • This PR's own secret-scan run is the acceptance check for the new scope.

🤖 Generated with Claude Code

…EAD)

gitleaks' git mode scans every fetched ref by default, and the job checks
out with fetch-depth 0, so one open branch's finding failed every other
pull request: PR #116's branch (four generic-api-key hits on 64-hex
fingerprint values, commit b801fe4) failed PR #117's required
secret-scan. Scanning HEAD's ancestry covers a pull request's merge commit
or main on push; each branch is still scanned by its own pull request.
Records the resolution of the scope decision .gitleaks.toml and
docs/github-automation.md had left to the coordinator.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T14:11:03.056751Z f1da1c9 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@seathatflowsinourveins
seathatflowsinourveins merged commit 05e134f into main Sep 23, 2026
16 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the claude/secret-scan-ancestry-scope-20260923 branch September 23, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant